Forum: Ruby on Rails Limit user ability to edit subset of data?

Announcement (2017-05-07): www.ruby-forum.com is now read-only since I unfortunately do not have the time to support and maintain the forum any more. Please see rubyonrails.org/community and ruby-lang.org/en/community for other Rails- und Ruby-related community platforms.
Tom T. (Guest)
on 2005-12-27 15:20
(Received via mailing list)
Hi all,

I have different types of user permissions on a site. Some users are
able to edit specific pages, some users have 'editor' rights, and some
have 'admin' rights.

I can render different views depending on the permissions the user has,
and restrict the ability to edit certain subsets of data through a form.
But how can I protect a user (who has permission to access the 'edit'
action) from submitting a raw POST request to edit specific fields that
they don't have permission to edit?

Thanks,

Tom
This topic is locked and can not be replied to.